📦 Experience Manager

by Adobe

🔍 What is Experience Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-64538

CRITICAL CVSS 9.3 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary JavaScript in victims' browsers. Successful explo...

CVE-2025-64539

CRITICAL CVSS 9.3 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary JavaScript in victims' browsers. Successful explo...

CVE-2025-64537

CRITICAL CVSS 9.3 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary JavaScript in victims' browsers. Successful explo...

CVE-2025-49533

CRITICAL CVSS 9.8 Jul 8, 2025

Adobe Experience Manager versions 6.5.23.0 and earlier contain a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code without user interaction. This affects al...

CVE-2020-24445

CRITICAL CVSS 9.0 Dec 10, 2020

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing these...

CVE-2025-54248

HIGH CVSS 7.7 Sep 9, 2025

Adobe Experience Manager versions 6.5.23.0 and earlier have an improper input validation vulnerability that allows low-privileged attackers to bypass security measures and gain unauthorized read acces...

CVE-2025-46840

HIGH CVSS 8.7 Jun 10, 2025

CVE-2025-46840 is an improper authorization vulnerability in Adobe Experience Manager that allows low-privileged attackers to bypass security controls and escalate privileges. Exploitation requires us...

CVE-2024-26029

HIGH CVSS 7.5 Jun 13, 2024

CVE-2024-26029 is an improper access control vulnerability in Adobe Experience Manager that allows attackers to bypass security features and potentially access sensitive information. This affects AEM ...

CVE-2021-43764

HIGH CVSS 8.0 Jan 13, 2022

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form fields. When users visit pages containing these co...

CVE-2021-44176

HIGH CVSS 8.1 Jan 13, 2022

This stored XSS vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form fields. When users visit pages containing these compromised fields, their...

CVE-2021-43761

HIGH CVSS 8.0 Jan 13, 2022

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) allows attackers to inject malicious scripts into form fields, which execute in victims' browsers when they visit...

CVE-2021-21083

HIGH CVSS 7.5 Jun 28, 2021

This vulnerability allows unauthenticated attackers to trigger a denial-of-service condition in Adobe Experience Manager (AEM) by exploiting improper access controls. Affected systems include AEM Clou...

CVE-2025-64873

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored Cross-Site Scripting vulnerability that allows low-privileged attackers to inject malicious JavaScript into form fields. When vict...

CVE-2025-64875

MEDIUM CVSS 5.4 Dec 10, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages cont...

CVE-2025-64881

MEDIUM CVSS 5.4 Dec 10, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages cont...

CVE-2025-64887

MEDIUM CVSS 5.4 Dec 10, 2025

This DOM-based XSS vulnerability in Adobe Experience Manager allows low-privileged attackers to execute malicious JavaScript in victims' browsers when users interact with crafted URLs or manipulated p...

CVE-2025-64888

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows low-privileged attackers to execute malicious JavaScript in victims' browsers. E...

CVE-2025-64857

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored cross-site scripting vulnerability that allows low-privileged attackers to inject malicious scripts into form fields. When users v...

CVE-2025-64858

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored XSS vulnerability where low-privileged attackers can inject malicious scripts into form fields. When victims browse pages containi...

CVE-2025-64861

MEDIUM CVSS 5.4 Dec 10, 2025

This stored XSS vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into form fields. When victims browse pages containing the injected scripts, th...

CVE-2025-64863

MEDIUM CVSS 5.4 Dec 10, 2025

A stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into form fields. When victims browse pages containing the ...

CVE-2025-64869

MEDIUM CVSS 5.4 Dec 10, 2025

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When users visit pages cont...

CVE-2025-64872

MEDIUM CVSS 4.8 Dec 10, 2025

This stored XSS vulnerability in Adobe Experience Manager allows high-privileged attackers to inject malicious JavaScript into form fields. When victims browse pages containing the compromised fields,...

CVE-2025-64840

MEDIUM CVSS 5.4 Dec 10, 2025

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages c...

CVE-2025-64841

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored Cross-Site Scripting vulnerability that allows low-privileged attackers to inject malicious scripts into form fields. When users v...

CVE-2025-64845

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored cross-site scripting vulnerability in form fields. Low-privileged attackers can inject malicious JavaScript that executes in victi...

CVE-2025-64847

MEDIUM CVSS 5.4 Dec 10, 2025

This stored XSS vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into form fields. When victims browse pages containing the injected scripts, th...

CVE-2025-64850

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored Cross-Site Scripting vulnerability that allows low-privileged attackers to inject malicious JavaScript into form fields. When user...

CVE-2025-64852

MEDIUM CVSS 5.4 Dec 10, 2025

This stored XSS vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing these fields,...

CVE-2025-64853

MEDIUM CVSS 5.4 Dec 10, 2025

A stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious scripts into form fields, which execute in victims' browsers when they...

CVE-2025-64825

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored XSS vulnerability where low-privileged attackers can inject malicious scripts into form fields. When victims browse pages containi...

CVE-2025-64826

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored XSS vulnerability where low-privileged attackers can inject malicious scripts into form fields. When users visit pages with these ...

CVE-2025-64827

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored Cross-Site Scripting vulnerability that allows low-privileged attackers to inject malicious JavaScript into form fields. When vict...

CVE-2025-64829

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored XSS vulnerability that allows low-privileged attackers to inject malicious JavaScript into form fields. When users visit pages con...

CVE-2025-64833

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored cross-site scripting vulnerability in form fields. Low-privileged attackers can inject malicious JavaScript that executes in victi...

CVE-2025-64839

MEDIUM CVSS 5.4 Dec 10, 2025

This stored Cross-Site Scripting vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages contain...

CVE-2025-64814

MEDIUM CVSS 5.4 Dec 10, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages cont...

CVE-2025-64817

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored cross-site scripting vulnerability in form fields. Low-privileged attackers can inject malicious JavaScript that executes in victi...

CVE-2025-64820

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored cross-site scripting vulnerability in form fields. Low-privileged attackers can inject malicious JavaScript that executes in victi...

CVE-2025-64821

MEDIUM CVSS 5.4 Dec 10, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages cont...

CVE-2025-64822

MEDIUM CVSS 5.4 Dec 10, 2025

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages c...

CVE-2025-64823

MEDIUM CVSS 5.4 Dec 10, 2025

Adobe Experience Manager versions 6.5.23 and earlier contain a stored XSS vulnerability where low-privileged attackers can inject malicious scripts into form fields. When users visit pages containing ...